Getting to the Crux (Ransomware) of the Matter

July 21, 2025, 8:57 a.m.

Description

A new ransomware variant named Crux has been identified, claiming association with the BlackByte group. Observed in three separate incidents, Crux encrypts files with a .crux extension and leaves ransom notes. Initial access appears to involve Remote Desktop Protocol (RDP) using valid credentials. The ransomware executable, with varying names and locations, follows a distinct process tree involving svchost.exe, cmd.exe, and bcdedit.exe. It disables system recovery to hinder restoration attempts. Data exfiltration using Rclone was observed in one incident. The threat actor demonstrates prior knowledge of targeted infrastructures and prefers using legitimate Windows processes. While claiming BlackByte affiliation, this hasn't been independently verified.

Date

  • Created: July 21, 2025, 8:15 a.m.
  • Published: July 21, 2025, 8:15 a.m.
  • Modified: July 21, 2025, 8:57 a.m.

Indicators

  • c96d5a279c660bfa9b70b7b2d78de951daff80fe6ad5617882587cb8e971e88b
  • b45e6cce412d9968e7ea67466076e7bd2d533598a9dc182699c84a0b1f72e3e4
  • 667b7220f5df1b31dd2dd3d4aa1fedb4fdd2e8e5926cdacd744da7a7c6635932

Attack Patterns